Skip to main content

CWE archive

CWE-286 CVEs

Programmatic archive

31 CVEs tagged with CWE-2862 Critical, 12 High, 16 Medium, 1 Low, 0 Unrated.

CVE-2026-60135

Published Jul 24, 2026

An attacker can modify data that should be restricted to read‑only access.

CVSS 7.1 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-35638

Published Apr 9, 2026

OpenClaw before 2026.3.22 contains a privilege escalation vulnerability in the Control UI that allows unauthenticated sessions to retain self-declared privileged scopes without de…

CVSS 8.7 · High
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2025-64725

Published Dec 15, 2025

Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a different user. Version 5.15. contains a patch. As a worka…

CVSS 1.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-59943

Published Oct 3, 2025

phpMyFAQ is an open source FAQ web application. Versions 4.0-nightly-2025-10-03 and below do not enforce uniqueness of email addresses during user registration. This allows multip…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-7972

Published Aug 14, 2025

A security issue exists within the FactoryTalk Linx Network Browser. By modifying the process.env.NODE_ENV to ‘development’, the attacker can disable FTSP token validation. This b…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-48853

Published May 22, 2025

An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as a "non" root ASPECT user. This issue affects ASPECT-Enterpri…

CVSS 9.5 · Critical

CVE-2024-46671

Published Apr 8, 2025

An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below, version 7.0.11 and below widgets dashb…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-58105

Published Mar 25, 2025

A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on a…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6356

Published Feb 5, 2025

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which a…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-13041

Published Jan 9, 2025

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. When…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52359

Published Nov 19, 2024

IBM Concert Software 1.0.0, 1.0.1, 1.0.2, and 1.0.2.1 could allow an authenticated user to perform unauthorized actions that should be reserved to administrator used due to improp…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9312

Published Oct 10, 2024

Authd, through version 0.3.6, did not sufficiently randomize user IDs to prevent collisions. A local attacker who can register user names could spoof another user's ID and gain th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-26689

Published Sep 25, 2024

An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-35503

Published Apr 22, 2024

Improper verification of a user input in Open Source MANO v7-v12 allows an authenticated attacker to execute arbitrary code within the LCM module container via a Virtual Network F…

CVSS 7.5 · High

CVE-2024-29296

Published Apr 10, 2024

A user enumeration vulnerability was found in Portainer CE 2.19.4. This issue occurs during user authentication process, where a difference in response time could allow a remote u…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51750

Published Jan 11, 2024

ScaleFusion 10.5.2 does not properly limit users to the Edge application because file downloads can occur. NOTE: the vendor's position is "Not vulnerable if the default Windows de…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3907

Published Dec 17, 2023

A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows a project Maintainer to u…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3914

Published Sep 29, 2023

A business logic error in GitLab EE affecting all versions prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows access to internal projects. A service account is…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3115

Published Sep 29, 2023

An issue has been discovered in GitLab EE affecting all versions affecting all versions from 11.11 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Single Sign On…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 31 CVEsPage 1 of 2